← Blog
For individuals

That 65% Off Deal Is Too Good To Be True

Explore an AI summary

You find a brand you recognize, a product you wanted, and a discount too good to pass up. The site looks right. The logo is real, the product photos are the real ones, even the customer support email matches the company you know. You enter your card details and check out. Nothing about the experience felt wrong.

That is exactly the problem. Security researchers have just documented one of the largest fake-shop operations ever found, and it is built entirely on stores that look completely legitimate.

The network, named "DoppelCart" by the German security firm Nebty, runs more than 119,000 fake online stores. Their only job is to take your payment card details and send them straight to criminals. This is not phishing in your inbox. It is a fake storefront waiting for you to arrive on your own.


Key takeaways

  • DoppelCart is a network of more than 119,000 fake online stores, most on ".shop" web addresses, built to steal shoppers' payment card details (source).

  • The fakes copy real brands almost perfectly, including product catalogs, descriptions, images, and in some cases the brand's real customer support address, so there is often nothing visibly "off" to catch.

  • They lure shoppers with steep discounts, advertised as high as 65% off.

  • At checkout, the site collects your full card details and can even relay the one-time code your bank sends, which is meant to protect you.

  • The habit that actually protects you is to stop judging a site by how it looks and confirm where you actually are before you pay.


What DoppelCart actually is

DoppelCart is a single, industrial-scale operation running a huge network of counterfeit shops. The numbers are worth sitting with, because they show this is not a handful of scam sites but a factory.

Researchers at Nebty found more than 119,000 fraudulent shop domains, most of them on the ".shop" web address ending, and counted over 105,000 still active. It is the largest publicly documented fake-shop cluster by domain count, larger than the previous record holder, "BogusBazaar," which ran 75,000 sites and was linked to an estimated 850,000 fraudulent transactions (source).

The sites are mass-produced from the same template: researchers found that 96% of confirmed DoppelCart shops share identical build files and connect back to just 27 shared systems. In total, the network impersonates 44,182 different brands, with a median of two copycat stores per brand, and some brands cloned into 30 or more separate shops.

In other words, for tens of thousands of real stores, there is now a convincing fake (or several) sitting somewhere on the web, waiting to be found.


Why these fakes are so hard to spot

The old advice for spotting a scam site was to look for the obvious tells: bad spelling, broken images, a cheap-looking design. DoppelCart has none of those, and that is the whole point. We wrote recently about why modern scams no longer look like scams, and fake shops are a perfect example.

Three things make these stores especially convincing:

They copy the real brand's own content. The fake shops lift product catalogs, descriptions, branding, and images directly from the companies they impersonate. In some cases they even load images straight from the real company's servers, so the pictures are genuinely the brand's own.

They show the real support address. Some DoppelCart stores display the impersonated brand's real customer support email. Shoppers who never receive their order end up contacting the actual company, which had no idea a fake was using its name.

They use the discount to rush you. The fakes advertise big markdowns, in many cases up to 65% off. A deal that good is designed to make you act before you stop to check, which is the same pressure tactic used across almost every modern scam.

Put together, a shopper doing everything the old advice suggested, checking the logo, glancing at the design, reading the product page, would find nothing wrong. The store passes the eye test because it was built to.


What actually gets stolen

When Nebty examined the checkout pages, they found code designed to quietly collect everything needed to use your card, and more:

  • Card number, expiration date, and security code

  • Cardholder name

  • Email address, phone number, and physical address

All of it is sent to the criminals' servers in real time as you type. And there is a further twist that matters: the checkout code can also relay the one-time confirmation code your bank sends to approve a purchase. That code is supposed to be your safety net. Here it can be captured and used in the moment to push a fraudulent charge through.

So the damage is not limited to a single purchase you never receive. It is your full card details, your personal information, and potentially the very verification step meant to protect you, all handed over in one checkout.


How to shop without getting caught

The reassuring part is that a few simple habits neutralize almost all of this, because they do not depend on the fake looking fake.

Reach the store yourself. If you see an ad or a search result for a deal, do not click straight through to check out. Open the brand's real website by typing its address or using a bookmark, and see if the sale actually exists there. Fake shops rely on you arriving through their link.

Be suspicious of the discount, not just the design. A legitimate brand rarely sells its own current products at 50 to 65% off through an unfamiliar site. If the price is the main reason you are excited, that is the moment to slow down.

Check the web address, and be wary of unusual endings. Many of these fakes live on ".shop" addresses and slightly-off domain names. If the address does not clearly match the brand you think you are buying from, stop.

Pay in ways that protect you. Credit cards and trusted payment services offer stronger fraud protection than debit cards or bank transfers. If a store pushes you toward an unusual payment method, treat that as a red flag.

If you already paid, act fast. Contact your bank or card issuer, freeze or replace the card, and watch your statements. The sooner you report it, the more likely the charge can be stopped or reversed.


How Haven helps

This is the kind of threat Haven is built to catch, because it lives entirely in the browser at the moment you are about to act. Haven is a browser extension that checks whether a site truly is who it claims to be, rather than trusting how convincing it looks. When you land on a fake or impersonated store, Haven flags it as untrustworthy before you reach the checkout and hand over your card, no matter how perfectly the store copied the real brand.

That is the important difference from the old advice. "Look for something suspicious" asks you to spot a fake that was carefully built to have no tells. Haven does not judge the store by its appearance; it checks what the site actually is. If you are ever unsure about a link or a shop before you open it, you can also paste it into Haven's free link checker first.

To be clear about scope: Haven works at the page, in your browser. It flags the fake store before you buy. It is not your bank's fraud department and it cannot recover a charge you have already made, so if you have already paid on a site that turns out to be fake, contact your card issuer right away. What Haven does is help make sure you rarely reach that point.

If you want to get better at recognizing these sites yourself, our guide on how to tell if a website is legit walks through the checks that still work, and our piece on scams that show up as the top search result explains how fakes end up in front of you in the first place.

The lesson underneath the discount is a familiar one this year: you can no longer trust that a scam will look like a scam. A fake store can be a flawless copy of a real one. The only reliable defense is to stop judging a page by how it looks, and start confirming what it actually is.


About Haven

Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link or enter your details, flagging fake and impersonated sites, suspicious links, and look-alike pages. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.

Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

Frequently asked questions

What is DoppelCart?
DoppelCart is a large fraud network, uncovered by the security firm Nebty, that runs more than 119,000 fake online stores. The stores copy real brands and are built to steal shoppers' payment card details at checkout. Most of the sites use ".shop" web addresses, and researchers found more than 105,000 still active. It is the largest publicly documented fake-shop network by number of domains.
How can I tell if an online store is fake?
You often cannot tell by looking, because these fakes copy the real brand's logo, product photos, and descriptions exactly. The most reliable checks are behavioral, not visual: do not click straight through an ad or search result to buy, instead open the brand's real website yourself and confirm the deal exists there; be suspicious of very steep discounts (DoppelCart shops advertised up to 65% off); and check that the web address clearly matches the brand, being wary of unfamiliar endings like ".shop" or slightly-off domain names.
What information do fake shops steal at checkout?
Researchers found that DoppelCart checkout pages collect your full card number, expiration date, and security code, along with your name, email, phone number, and physical address, and send it all to the criminals in real time. The checkout code can also relay the one-time confirmation code your bank sends to approve a purchase, which means that safety step can be captured and used against you in the moment.
Why do fake stores look so real now?
Because copying a real store is cheap and easy. Fake shops lift product catalogs, descriptions, branding, and images directly from the companies they impersonate, and sometimes load images straight from the real brand's own servers. Some even display the real brand's customer support address. The old advice to look for bad spelling or clumsy design no longer helps, because these fakes are built to have no visible flaws.
What should I do if I entered my card details on a fake store?
Act quickly. Contact your bank or card issuer, report the site as fraudulent, and freeze or replace the affected card. Watch your statements closely for charges you did not make, and change any password you reused on that site. The sooner you report it, the better the chance a fraudulent charge can be stopped or reversed.
How does Haven protect against fake online stores?
Haven is a browser extension that checks whether a site truly is who it claims to be, rather than trusting how convincing it looks. When you land on a fake or impersonated store, Haven flags it as untrustworthy before you reach checkout and enter your card, no matter how perfectly it copied the real brand. It works at the page level in your browser and is free for individual use. Haven flags the fake before you buy; it is not a bank fraud service, so if you have already paid on a fake site, contact your card issuer right away.